BIOC Low

Tampering with the Windows System Restore configuration

System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005) Impact (TA0040)
ATT&CK techniques: Rootkit (T1014) Inhibit System Recovery (T1490)
Indicator:

Registry action type = set_registry_value , create_registry_key , delete_registry_value AND registry data = 1 AND registry key name = *Software\Microsoft\Windows Nt\SystemRestore\DisableSR Host host os = windows

Preventable: yes